Ransomware Victims Jump To 7,831 As AI Crime Tools Scale Global Attacks

Cybercrime is becoming faster, more organized, and more automated, according to Fortinet’s 2026 Global Threat Landscape Report.

The report says ransomware victims jumped to 7,831 in 2025, up from about 1,600 the year before, as AI-powered crime tools helped attackers scale their operations.

Fortinet says modern cybercrime now works like a system, not a set of isolated incidents. Attackers are using AI to speed up reconnaissance, weaponization, and exploitation, which is shrinking the time defenders have to react.

The report says time-to-exploit for critical issues has fallen to as little as 24 to 48 hours, down from 4.76 days in earlier reporting.

It also notes that exploitation attempts can begin within hours of a vulnerability being disclosed, leaving little room for patch delays.

Fortinet researchers also point to “shadow agents” and crime-service kits such as WormGPT, FraudGPT, and BruteForceAI as part of the new attack model.

These tools lower the skill needed to launch attacks and help criminals automate tasks that once required more effort and experience.

Ransomware Targets Widen

The report identifies manufacturing, business services, and retail as the top ransomware targets, with the U.S., Canada, and Germany leading by volume.

Fortinet says the spread reflects how attackers now choose targets based on scale, exposed data, and business impact.

Fortinet also says cloud compromise is often driven by stolen or misused credentials rather than direct infrastructure attacks.

That makes identity protection a major weak point, especially in sectors with large user bases and complex access systems such as hospitals and retail.

The report adds that credential-stealer malware remains a major source of risk. FortiRecon telemetry shows large infection counts tied to malware families such as RedLine, Lumma, and Vidar, which feed stolen data into the broader cybercrime economy.

Fortinet says defenders now need AI-enabled security operations that can respond at the same speed as the threat actors.

The company argues that security teams must move toward industrialized defense, using automation, threat intelligence, and faster response workflows.

The report also highlights disruption efforts with law enforcement and public-private groups, including operations linked to INTERPOL and the Cybercrime Atlas.

Those efforts aim to map criminal networks, break infrastructure, and make cybercrime harder to scale.

The big message from the report is simple: cybercrime is no longer slow or isolated. It is faster, more connected, and increasingly powered by AI, which means both prevention and response now have to move much quicker.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories